Description
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2398-1 | puma security update |
EUVD |
EUVD-2020-0447 | In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4. |
Github GHSA |
GHSA-x7jg-6pwg-fx5h | HTTP Smuggling via Transfer-Encoding Header in Puma |
Ubuntu USN |
USN-6682-1 | Puma vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T11:21:14.684Z
Reserved: 2020-03-30T00:00:00.000Z
Link: CVE-2020-11076
No data.
Status : Modified
Published: 2020-05-22T15:15:11.363
Modified: 2024-11-21T04:56:44.090
Link: CVE-2020-11076
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN